Legal

Privacy Policy

Last updated June 2026

Overview

This policy explains what PebbleSpace collects, why, and how it is handled. PebbleSpace is designed to collect only what it needs to run a version-control platform — nothing is sold or used for advertising.

What we collect

  • Account data — your username, display name, email, and (hashed) password.
  • Content — the repositories, commits, and metadata you push.
  • Operational data — sessions, API tokens (stored hashed), and audit logs of actions on your account.
  • Technical data — IP address and basic request metadata, used for security and abuse prevention.

How we use it

  • To authenticate you and operate the features you use.
  • To secure the platform — detecting abuse and maintaining the audit trail.
  • To send essential service email (verification, password resets, security notices).

Cookies & sessions

We use a single, secure session cookie to keep you signed in. There are no third-party advertising or tracking cookies. Signing out invalidates the session.

Third-party sign-in

If you sign in with GitHub or Google, we receive only the basic profile and email needed to create your account. We never receive your password for those providers.

Retention & your rights

Your data is retained while your account is active. You can update your profile, revoke API tokens and sessions, and request deletion of your account, which removes your personal data and repositories from the platform.

Security

Passwords are hashed with scrypt, tokens and session identifiers are stored hashed, and requests are CSRF protected. No system is perfectly secure, so keep your credentials safe and your own backups current.

Contact

For privacy questions or a deletion request, contact the administrator of this instance through the channel published in your workspace. See also our Terms of Service.